The phishing red flags that catch nearly every fake email group into four clusters: the sender, the pressure, the link and the money. If an email trips three or more, treat it as hostile until someone verifies it through another channel — and in 2026, when AI writes flawless prose, the flags that remain reliable are almost all structural.
Key takeaways
- Most phishing fails on structure, not spelling: sender mismatch, urgency, link mismatch and payment changes drive the bulk of real detections.
- An email that changes payment details or asks for credentials deserves verification no matter how ordinary it looks.
- Report through the email report button rather than deleting — phishing simulations train that reflex safely.
- Perfect grammar is no longer evidence of legitimacy in 2026; AI drafts read like your colleagues.
The sender red flags
- Display name and address disagree. A message signed CFO Sarah Nguyen but sent from a personal Gmail address is not your CFO.
- Look-alike domains. Swapped letters and added words — yourbank.com.au versus your-bank.com.au — are the oldest trick and still among the most profitable.
- Reply-to differs from the sender. The reply goes to a different address than the one the message arrived from; check before answering.
- Unexpected external banner or unknown correspondent. An external-sender tag on mail you expected to be internal, or an unknown sender asking for anything.
The pressure red flags
- A deadline measured in hours. Genuine businesses give you time to verify; fraudsters give you minutes.
- Secrecy instructions. Keep this between us, do not loop in IT, the CEO is in meetings all day.
- Threats of consequence. Account closure, penalty, legal action, an expired subscription — the pressure is the payload.
- Something for nothing. Refunds, prizes or tax rebates you never applied for.
The link and attachment red flags
- Hover reveals a mismatch. The text says your bank; the tooltip shows a hyphenated string on a different domain.
- Shortened or wrapped links. Shortener links and surprise redirects hide the destination on purpose.
- Unexpected attachments. Especially invoices you never ordered, zip archives and files that open a browser login page.
- QR codes inside email. They push the action onto your phone, away from the corporate filter that would have caught it.
The money and data red flags
- Changed bank details. Any change to payment instructions is verified by phone, using a number you already had — never one from the email.
- Requests for credentials or codes. Nobody legitimate needs your password, an MFA code or a gift card purchase.
- Personal data requests. Staff lists, customer contact details, tax file numbers — especially combined with urgency.
How to use the checklist
| Situation | Move |
|---|---|
| One or two flags | Verify through a known channel before acting |
| Three or more flags | Treat as hostile, report, do not interact |
| Payment details changed | Phone the known number before any payment |
| Credentials already entered | Incident response, immediately |
Why the checklist still works in the AI era
Generated phishing has erased the typo tell: messages in 2026 are grammatically flawless and personalised with scraped details. What AI has not erased is the structural mismatch — the reply-to, the domain, the changed account, the urgency. Those live in the attacker's infrastructure and timeline, not their prose. Verizon's 2025 Data Breach Investigations Report analysed 12,195 confirmed breaches and again found a human element in roughly 60% of them (full report PDF); the checklist exists because that 60% is decided in seconds at the desk, not in a security review.
Turning the checklist into a reflex
A checklist in a policy document stops zero phishing. The reflex forms through repetition: monthly micro-lessons built around real local lures, simulations that exercise exactly these flags, and a report button that makes the correct action one click. Cyber Aware's security awareness training sequences monthly lessons and simulations this way, and the platform comparison shows how vendors differ on the same-day coaching loop that makes the lesson stick.
What to do the moment you spot a red flag
Do not click, do not forward to colleagues, do not reply to test it. Use the report button so the message is captured and pulled from other mailboxes, then tell the recipient's manager or IT by voice. If you already clicked or entered credentials, skip the checklist and go straight to credential resets and your incident process.
FAQ
What are the most common phishing red flags? Sender-address mismatch, artificial urgency, link destinations that disagree with the link text, and any change to payment details.
What is the single most reliable red flag? A request that bypasses normal process — changed bank details or credentials asked for by email. Verification through a known channel defeats it.
Can AI-written phishing be spotted? Yes — structural flags still work. Perfect grammar is no longer a sign of legitimacy, so judge the sender, the links and the request, not the prose.
Do the same flags apply to SMS and chat messages? Mostly. Urgency, links and payment requests transfer directly; sender checks become number and account checks.
What should I do if I already clicked? Reset the credentials for any account you touched, report it immediately, and follow your incident steps — speed limits the damage more than anything else.
How often should staff rehearse the checklist? Monthly. A lesson and one simulation per month keep the flags current with what attackers are actually sending in 2026.
One last thing
The most dangerous email is not the obvious scam. It is the plausible one that trips exactly one flag — a changed bank detail on an otherwise perfect invoice thread. Processes beat perception: verification steps for payments and credentials catch what reading never will.